1) Data controller: The data controller is TechMate Kamil Kołcz, tax ID (NIP) 7952252646, based at ul. Sołtysowska 10L, Kraków, Poland, e-mail: [email protected] (hereinafter the “Controller”). For privacy-related matters, contact the Controller at the e-mail address above or via the contact form on this website.

2) Scope of data processed: Depending on how you contact us and what you provide, the Controller may process in particular: name or contact person designation; e-mail address; phone number if provided; company name and company details if provided; information in the message content; information submitted via the project brief, in particular about the planned project, service scope, requirements and budget if provided; technical data related to use of the website such as IP address and browser, device or OS information — to the extent necessary for security and proper operation. The Controller processes only data necessary for the stated purposes.

3) Purposes of processing: Personal data may be processed to: reply to enquiries sent via the contact form; handle correspondence and contact with the user; prepare an offer, quote or response regarding a planned project; take steps at the user’s request prior to entering into a contract; perform a concluded contract if cooperation begins; ensure website security, including protecting forms against spam, bots and other abuse; enable assistance with filling in the contact form via an in-browser AI agent (WebMCP) where the browser supports it — with the user remaining in control of submission; establish, exercise or defend legal claims; fulfil legal obligations of the Controller.

4) Legal bases: Personal data may be processed on the basis of: Art. 6(1)(b) GDPR — where processing is necessary to take steps at the user’s request prior to entering into a contract or to perform a concluded contract; Art. 6(1)(f) GDPR — where processing is necessary for the Controller’s legitimate interests, in particular handling correspondence, ensuring website security and establishing, exercising or defending claims; Art. 6(1)(c) GDPR — where processing is necessary to comply with a legal obligation of the Controller; Art. 6(1)(a) GDPR — where processing is based on the user’s voluntary consent.

5) Recipients: Data may be shared with entities supporting the Controller in operating the website and handling contact, in particular: hosting and server infrastructure providers; e-mail and communication service providers; security service providers, including Cloudflare; IT and technical support providers; other entities where necessary for a processing purpose or required by law. The website uses Cloudflare Turnstile to protect forms against automated abuse, spam and bots. The contact form may be assisted by WebMCP (a browser API / AI agent on the user’s side); form data still reach the Controller via the same path as manual completion (in particular e-mail). As of the last update of this Privacy Policy, the website does not actively use analytics tools such as Microsoft Clarity or Google Analytics. If such a tool is enabled in future, information about its use and the legal basis will be updated in this Privacy Policy and the Cookie Policy.

6) Transfers outside the European Economic Area: Due to use of certain external providers, personal data may be transferred to or accessible from outside the EEA, including the United States. In such cases the Controller uses appropriate safeguards under data protection law, in particular Standard Contractual Clauses (SCC), adequacy decisions or other legally permitted transfer mechanisms.

7) Retention: Personal data related to a contact enquiry or brief are stored for as long as needed to handle the enquiry, correspondence and offer preparation, and then as a rule for up to 12 months after commercial contact ends. If a contract is concluded, data necessary for performance may be stored for the term of the contract and then for periods required by law or needed to establish, exercise or defend claims. Data processed to fulfil legal obligations, in particular tax and accounting duties, are stored for periods resulting from applicable law.

8) Your rights: To the extent provided by the GDPR, you have the right to: access your personal data; rectification; erasure; restriction of processing; data portability; object to processing based on Art. 6(1)(e) or (f) GDPR; withdraw consent where processing is based on consent. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal. You may also lodge a complaint with the President of the Personal Data Protection Office (UODO) if you consider that processing of your personal data infringes data protection law.

9) Voluntary provision of data: Providing data in the contact form or brief is voluntary. Providing data marked as required may however be necessary to reply to an enquiry, prepare an offer or take steps prior to entering into a contract. You decide what additional information to include in the message or brief.

10) Automated decision-making and profiling: The Controller does not make decisions concerning users based solely on automated processing of personal data, including profiling, that would produce legal effects concerning the user or similarly significantly affect them.

11) Source of data: Personal data are obtained directly from the data subject, in particular via the contact form, brief, e-mail or other contact channels available on the website.

12) Data security: The Controller applies appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Form protection may use Cloudflare security solutions, including Cloudflare Turnstile.

13) Changes to this Privacy Policy: The Controller may update this Privacy Policy in particular where the website, services used or applicable law change. The current version is published on the website.

Last updated: 8 August 2026.

· Contact